Researchers disclosed an agent-to-agent exploitation chain in Google’s open-source adk-python repository for the Agent Development Kit, showing how a low-privilege public-facing AI agent handling GitHub issues and pull requests could be prompt-injected into triggering a higher-privilege maintainer-only agent. The attack abused trusted handoffs between agents and GitHub workflow visibility to create a plausible malicious review trail, potentially steering maintainers toward merging poisoned pull requests and opening a software supply-chain compromise path.
The researchers also reported a second weakness in Antigravity SDK-based automation, where a command allowlist could be bypassed through Git scripting features to achieve remote code execution on the CI runner. Because the runner reportedly exposed a long-lived personal access token and Google Cloud service account credentials, even an unprivileged GitHub issue could have enabled secret exfiltration. Google said it fixed and hardened the repository and credited the report, while declining a bug-bounty payout because successful exploitation still depended on social engineering and maintainer action.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Google confirmed that the second Antigravity-based vulnerability in the adk-python repository was remediated on July 21, 2026. The flaw had allowed agent-to-agent prompt injection to reach CI runner code execution and expose sensitive environment variables.
Dark Reading reports that after Pillar Security disclosed the initial agent-to-agent exploitation chain in early June 2026, Google remediated the first set of issues on July 9, 2026. This remediation preceded the separate July 21 fix for the second Antigravity-based weakness.
Pillar Security said that on July 2 it confirmed the affected Antigravity-based workflows in Google's adk-python repository had been removed. The removed workflows were part of the second attack path that allowed prompt injection from a public issue to reach a trusted fixing workflow.
After Pillar Security reported a second vulnerability involving Antigravity-SDK-based automation in the google/adk-python repository, Google fixed the weakness in late July. Pillar said the flaw could have enabled remote code execution without maintainer interaction.
Google deleted the issue-analyze, issue-fix, and pr-analyze GitHub Actions workflows from the public adk-python repository, stating they ran automated agents on untrusted issue and pull request content with broad repository credentials. The commit removed the exposed workflows as a mitigation while a safer design was considered.
Dan Lisichkin planned to discuss the findings at DEF CON's AI Village. The talk was scheduled for August 7.
After the initial disclosure, researchers found a second vulnerability in newly added Antigravity SDK-based automation in the same repository. They reported that a command allowlist could be bypassed via git scripting features to achieve CI runner code execution and potentially exfiltrate a long-lived personal access token and Google Cloud service account credentials from an unprivileged GitHub issue.
Google declined to award a bug bounty because it considered the exploit chain dependent on social engineering and maintainer action, but said it would recognize the report with credit. Another account states Pillar Security received an honorable mention for the disclosure.
After the disclosure, Google fixed the underlying repository issue and hardened the adk-python repository. Google confirmed the findings, said the demonstrated token had pull-request-related write permissions, and noted that maintainer action would still have been required to merge malicious code.
Pillar Security researchers disclosed a practical exploitation chain in Google's open-source google/adk-python repository, showing that a low-privilege public-facing AI triage agent could be prompt-injected into triggering a higher-privilege maintainer workflow. The reported path could fabricate a trusted approval trail for a malicious pull request and create a potential software supply-chain compromise route.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcedarkreading.com
Open sourceinfoworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcepillar.security
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.